Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Apache Syncope — Vulnerabilities & Security Advisories 22

All 22 CVE vulnerabilities found in Apache Syncope, with AI-generated Chinese analysis, references, and POCs.

Apache Syncope is an open-source identity and access management solution developed by the Apache Software Foundation, which contains a variety of common weakness types including cross-site scripting, improper input validation, and security misconfigurations. This aggregation page collects documented vulnerabilities affecting Apache Syncope, ranging from its initial releases through recent versions, covering security issues reported between 2014 and the present day. By exploring this resource, security professionals can track the evolution of advisories issued by the vendor, gain a deeper understanding of specific weakness classes within the context of identity management systems, and look up the complete vulnerability history for the product to assess its long-term security posture. The data is organized to facilitate efficient cross-referencing between different vulnerability categories, allowing users to identify patterns in defect types and prioritize remediation efforts based on severity and exposure. This structured approach helps administrators and developers maintain awareness of potential risks associated with their deployment environments without needing to sift through disparate sources. All entries are derived from official advisories, public databases, and verified security reports, ensuring accuracy and reliability for incident response and compliance auditing purposes.

Vendor: Apache Software Foundation

CVE IDTitleCVSSSeverityPublished
CVE-2026-62418 Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check CWE-918--2026-07-20
CVE-2026-62183 Apache Syncope: User self-service privilege escalation CWE-269--2026-07-20
CVE-2026-57308 Apache Syncope: SQL injection vulnerability in Audit Events search CWE-89--2026-07-20
CVE-2026-53421 Apache Syncope: Remote Code Execution via Scripted Connector CWE-653--2026-07-20
CVE-2026-53405 Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask CWE-653--2026-07-20
CVE-2026-63071 Apache Syncope: RCE via Groovy Sandbox bypass CWE-653--2026-07-20
CVE-2026-42797 Apache Syncope: JexlContextBuilder Information Disclosure CWE-202--2026-05-25
CVE-2026-42782 Apache Syncope: Post-auth RCE via Groovy static CWE-653--2026-05-25
CVE-2026-23794 Apache Syncope: Reflected XSS on Enduser Login CWE-79 6.1AIMediumAI2026-02-03
CVE-2026-23795 Apache Syncope: Console XXE on Keymaster parameters CWE-611 4.9AIMediumAI2026-02-03
CVE-2025-65998 Apache Syncope: Default AES key used for internal password encryption CWE-321 6.5AIMediumAI2025-11-24
CVE-2025-57738 Apache Syncope: Remote Code Execution by delegated administrators CWE-653 7.2AIHighAI2025-10-20
CVE-2024-45031 Apache Syncope: Stored XSS in Console and Enduser CWE-79 5.4AIMediumAI2024-10-24
CVE-2024-38503 Apache Syncope: HTML tags can be injected into Console or Enduser text fields CWE-79 5.4AIMediumAI2024-07-22
CVE-2020-11977 Apache Syncope 安全漏洞 7.2 -2020-09-15
CVE-2020-1961 Apache Syncope 注入漏洞 9.8 -2020-05-04
CVE-2019-17557 Apache Syncope 跨站脚本漏洞 5.4 -2020-05-04
CVE-2020-1959 Apache Syncope 代码注入漏洞 9.8 -2020-05-04
CVE-2018-17186 Apache Syncope 安全漏洞 7.2 -2018-11-06
CVE-2018-17184 Apache Syncope 跨站脚本漏洞 5.4 -2018-11-06
CVE-2018-1321 Apache Syncope 安全漏洞 7.2 -2018-03-20
CVE-2018-1322 Apache Syncope 安全漏洞 4.9 -2018-03-20

All 22 known CVE vulnerabilities affecting Apache Syncope with full Chinese analysis, references, and POCs where available.